Cybersecurity

Application Security
Rejetto HFS Flaw Lets Hackers Forge Admin Sessions for RCE
A critical Rejetto HFS flaw, CVE-2026-61500, lets attackers forge admin session cookies and gain remote code execution; active exploitation began October 1.
Cybersecurity
Citrix Patches New NetScaler Zero-Day Hit by Active Attacks
Citrix released emergency patches for CVE-2026-88779, a NetScaler SAML zero-day under active attack that can knock enterprise login gateways offline for users.
Cybersecurity
South Korea’s President Orders Probe Into Bank Data Breaches
President Lee Jae Myung ordered an investigation after breaches at Shinhan, KB Kookmin, Hana, Woori, and Yegaram Savings Bank exposed over 60,000 records.
Cybersecurity
Alleged ShinyHunters Leader ‘Rey’ Reportedly Held in Jordan
A suspected ShinyHunters member known online as Rey was reportedly detained in Jordan on September 29 and is said to be cooperating with FBI investigators.
Cybersecurity
Nikkei Discloses M365 Breach, 9,000 Spoofed Emails Sent
Nikkei disclosed a Microsoft 365 account breach that sent 9,000 spoofed emails to contacts, plus a separate cloud intrusion exposing data on 1,646 people.
Application Security
Google Pauses Open-Source Bug Bounty Over AI Report Flood
Google stopped accepting new submissions to its open-source bug bounty program after a flood of low-quality, AI-generated vulnerability reports arrived.
CVE Vulnerability Alerts
Critical FortiMail Zero-Day Exploited With No Patch Yet
Fortinet confirmed active exploitation of a critical FortiMail flaw with no fix shipped for most versions, and CISA added it to its exploited list.
Cybersecurity
Police Dismantle KillSec Ransomware Gang, Nab Teen Leader
A ten-country police operation seized KillSec's servers and leak site, arrested a suspected 16-year-old ringleader, and recovered over 110TB of stolen data.
Application Security
Kiteworks Patches Second Max-Severity Flaw in a Week
Kiteworks patched a maximum-severity code injection flaw found through its bug bounty program, marking its second critical disclosure in roughly a week.
Application Security
Self-Healing WordPress Backdoor Defies Standard Removal
Sucuri found a WordPress backdoor, SC, that persists across eight file, database, and memory locations and rebuilds itself when any one is deleted.